It's buried in the bottom of the post, but I'm happy to see that Facebook paid a bug bounty of $10,000 for this. In the past we've seen Facebook refuse to pay bug bounties when the hacker goes beyond scope. Interesting that going beyond the usually scope of bug bounties actually discovered a latent exploit and helped Facebook. Maybe this will result in change of policies for bounty scope.

